CVE-2023-23987: WordPress User Registration plugin <= 2.3.0 - Cross Site Scripting (XSS)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPEverest User Registration plugin <= 2.3.0 versions.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpeverest User Registration user-registration allows DOM-Based XSS.This issue affects User Registration: from n/a through <= 2.3.0.
— NVD
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-23987?
The severity of CVE-2023-23987 is medium.
What is the vulnerability description of CVE-2023-23987?
CVE-2023-23987 is a stored Cross-Site Scripting (XSS) vulnerability in WPEverest User Registration plugin version <= 2.3.0.
How can an attacker exploit CVE-2023-23987?
An attacker with admin+ privileges can exploit CVE-2023-23987 by injecting malicious scripts into stored data that will be executed by users who view the affected content.
What is the affected software of CVE-2023-23987?
The affected software of CVE-2023-23987 is WPEverest User Registration plugin version <= 2.3.0.
Is there a patch available for CVE-2023-23987?
Yes, a patch is available for CVE-2023-23987. Please refer to the reference link for more information.